Privacy Policy
Last updated: July 27, 2026
1. Who we are
Sorcerer Inc. ("Sorcerer", "we") is the data controller for the personal data described in this policy. Contact for any privacy matter, including requests: bugs@sorcerer.app.
2. What we collect
The Sorcerer desktop App collects nothing: it runs offline, with no telemetry, no analytics, and no crash reporting. Data collection happens only on the Portal (sorcerers.app), and only this:
- Email address — your account identifier, used for passwordless sign-in (magic links) and license delivery.
- Session metadata — IP address and browser user agent, stored with each Portal session and in security audit logs.
- License data — license key ID, purchase date, status, and the hardware ID of the Mac where the license is activated.
- Support correspondence — if you email us, we keep the conversation to help you.
Payment details (card number, billing data) are processed directly by Dodo Payments, our merchant of record. We never see or store them.
3. Why we use it (legal bases)
- Performing our contract with you (LGPD art. 7, V; GDPR art. 6(1)(b)): delivering your license, binding it to your machine, enabling transfers, and authenticating you on the Portal.
- Legitimate interest (LGPD art. 7, IX; GDPR art. 6(1)(f)): securing the Portal, preventing fraud and license abuse, and keeping audit logs.
- Legal obligation (LGPD art. 7, II; GDPR art. 6(1)(c)): keeping purchase records for tax and accounting requirements.
4. Who processes data for us
- Dodo Payments — payment processing and merchant-of-record duties.
- Resend — delivery of transactional email (magic links, license keys, receipts).
- Our hosting provider — runs the servers where the Portal database lives.
- Cloudflare — access protection for the administrative area.
We do not sell, rent, or share your personal data with anyone else, and there are no advertising or tracking partners.
5. Cookies
The Portal uses a single cookie: a signed, HTTP-only session cookie that keeps you signed in. It is strictly necessary for the service to work, so no consent banner is required. There are no analytics, marketing, or third-party cookies. The landing page sets no cookies at all.
6. Retention
Account data lives until you delete your account (self-service, in the Portal) — deletion destroys your sessions and removes your profile. License and purchase records are kept for the period required by applicable tax law, since they document a perpetual license you may reactivate later. Security audit logs are kept for a limited period and then discarded.
7. Your rights
Under the LGPD (Brazil) and the GDPR (EU/EEA), you have the right to: confirm and access your data, correct it, delete it, request portability, and object to or restrict processing. You can exercise most of these yourself in the Portal (view your data, change your email, delete your account), or by emailing bugs@sorcerer.app. You also have the right to lodge a complaint with your supervisory authority — in Brazil, the ANPD; in the EU/EEA, your local data protection authority.
8. International transfers
Our processors may be located in countries other than yours. When personal data is transferred internationally, we rely on the safeguards provided by those processors and on the legal bases described above.
9. Security
The Portal is served over HTTPS, sign-in is passwordless (no password database to leak), sessions are signed and HTTP-only, and the administrative area is protected by an additional identity-aware proxy. The App itself holds no personal data of yours beyond what stays on your own machine.
10. Children
Sorcerer is not directed at children under 13, and we do not knowingly collect their data. If you believe a child has created an account, email us and we will delete it.
11. Changes
We may update this policy; the current version is always at sorcerers.app/privacy with the revision date at the top. Material changes will be announced on the landing page before they take effect.